Job Title: Vulnerability Identification, Remediation, And Mitigation / Vulnerability Management
Location: Fort Meade, MD
SRG is looking for experienced Vulnerability Analysts to support Joint Force Headquarters – Department of Defense Networks (JFHQ-DODIN) in analyzing software/hardware vulnerabilities and the impact those vulnerabilities will have to DoD systems and the contribute to the mitigation strategies.
· Establish communications with vendors for the release of newly identified vulnerabilities and to ensure they understand the specialized requirements of DoD information systems.
· Leverage a specialized understanding of vendor products and fix actions to develop mitigations orders for the identified vulnerabilities.
· Compile daily, weekly and annual vulnerability metrics associated with affected and non-affected DoD products.
· Utilize the tracking tools to upload information for DoD component consumption and vulnerability compliance tracking.
· Develop, staff, and maintain accurate JFHQ-DODIN orders.
· Create situational awareness products to provide DoD components with detailed information related to vulnerabilities and appropriate mitigation strategies.
· Identify, analyze, and develop mitigation or remediation actions for system and network vulnerabilities.
· Prioritize identified vulnerabilities based upon severity, potential operational impact, and other factors for DoD.
· Conduct open source research to identify and analyze known and unknown vulnerabilities.
· Analyze issues affecting DoD components with vendor provided fixes and contact the appropriate vendor for a defined and attainable solution.
· Conduct coordination with DISA/FSO, DoD Combatant Commands, Services, Agencies, Field Activities, Intelligence Agencies, LE, US Government organizations.
· Provide notification of potential threats by tracking vulnerabilities and exploits, propagation of worms and viruses as they migrate throughout DoD and globally Develop, staff, and release analysis findings in technical analysis reports to DoD Community
- Active DoD TS/SCI clearance
- Proficient in developing briefing materials, administrative, and logistics support
- Have a working understanding of the Risk Management Framework (RMF).
- Have specialized knowledge in computer network theory and understand IT standards, including the OSI model, and the methods of exploiting those standards.
- Have strong interpersonal, organizational and critical thinking/problem solving skills
- Must be flexible, dependable and be able to multi-task with priorities
- Knowledge of Host Base Security Systems (HBSS)
3 years experience with IA Experience with and/or a working knowledge of the following :
- Networking infrastructure: routers, switches, and web security gateway
- TCP/IP Protocols and Services
- Identification and Access Management
- SIEM Reports
- Knowledge of Tanium
- Enterprise Mission Assurance Support Service (eMASS)
- Experience at USCYBERCOM or Cyber Service Centers or equivalent.
- Demonstrated understanding of cyber advanced persistent threats, actors, infrastructure, and TTP's.
- Demonstrate understanding of defensive cyber operations to include cyber incident response, and Intrusion Detection Systems (IDS).
- Experience with network analysis and coursework preferred.
- MA or MS degree preferred.
- DoD 8570 IAT Level II
- Certification in any of the following areas: A+, Network+, Security+, CISSP
SRG Commercial is a leading provider of information technology, training, engineering, accounting and intelligence analytical services for agencies in the intelligence, defense, homeland security, cyber security, and federal civilian markets. SRG utilizes an innovative approach to identify and qualify talent that is unique to the federal contracting industry, featuring a cutting edge platform that allows us to rapidly and precisely match professionals to client requirements. We have a proprietary database of over one million candidates and maintain continuous contact with our qualified talent.
Intrusion Detection Systems
Security Information And Event Management